cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1353
Views
5
Helpful
1
Replies

ISE CA certificate key usage bit for key Encipherment or Key Agreement missing

DammeneSalah_2
Level 1
Level 1

Hi

Generate the CA certificate from Microsoft Server Window 2008 R2, create  a new web server certificate template, add the client authentication on  the extension tab for EKU. Other option remain default setting.

I trying to import this certificate into Cisco Identity Service Engine  it showing error. Well, the CSR is generated from this appliance  somehow, key length is 2048 and SHA-256, save as .pem format.

The error it show as

"Certificate does not have required key usage (key usage bits for KeyEncipterment or KeyAgreement are missing)"

Please advice, thanks

Salah

1 Reply 1

Peter Koltl
Level 7
Level 7

The Server authentication EKU is needed, not the Client authentication.